Base solution for your next web application
Open Closed

Validate Attachments #12603


User avatar
0
smartech created

Hi Team

We are planning to conduct a PT on the application, we have requested by the vendor to validate the attachments and make sure the attachments not vulnerable. Also, they request us to scan the files with antivirus scanning services.

Any recommendations here ?

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

3 Answer(s)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @smartech

    ASP.NET Zero provides a multi layer file upload validation mechanism to reduce risks related to malicious attachments. The built in file validation pipeline includes:

    • Extension Whitelisting Only explicitly allowed file extensions can be uploaded.

    • MIME Type Validation Uploaded files are validated against their declared Content Type.

    • File Size Limits Configurable maximum size restrictions are enforced per file upload.

    Supported file categories typically include images, documents, and text based files, depending on application configuration.

    Antivirus Scanning

    ASP.NET Zero does not include antivirus scanning by default, as scanning strategies depend heavily on infrastructure and compliance requirements. However, the upload pipeline is designed to be extensible, and antivirus scanning can be integrated before persistence of the file.

    Commonly used and supported integration approaches include:

    • ClamAV (self hosted or container based scanning)
    • Windows Defender (for on premise Windows environments)
    • Cloud based services such as VirusTotal API or Azure Defender for Storage
    • Custom ICAP based scanning services

    A recommended approach is to block file persistence until the scan completes and reject uploads flagged as malicious.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    smartech created

    How you are testing the PDF files contains malicious code ?

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @smartech

    ASP.NET Zero’s built in PdfFileValidator performs structural validation on uploaded PDF files. This validation includes:

    • Extension validation Only .pdf files are accepted.

    • MIME type validation Verifies that the uploaded file declares the application/pdf content type.

    • Magic bytes (file signature) validation Ensures the file starts with the %PDF header (0x25 0x50 0x44 0x46).

    These checks confirm that the uploaded file is a valid PDF file structurally. However, they do not detect malicious payloads embedded inside a valid PDF, such as:

    • Embedded JavaScript
    • Launch Actions
    • Embedded executables
    • Exploit code targeting PDF reader vulnerabilities

    Detection of such threats requires antivirus or sandbox based scanning.

    Malicious Content Detection

    For advanced malicious content detection, one of the following integrations is recommended:

    | Approach | Description | | ------------------------------ | ------------------------------------------------------------------------------------------------------------------------------- | | ClamAV | Open source antivirus engine. Can be self hosted or containerized. For .NET integration, the nClam NuGet package can be used. | | Windows Defender / AMSI | Suitable for on premise Windows environments. Files can be scanned via the Anti Malware Scan Interface (AMSI). | | VirusTotal API | Cloud based scanning using 70+ antivirus engines. Recommended for low volume uploads. | | Azure Defender for Storage | If Azure Blob Storage is used, uploaded files are automatically scanned. |

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)